Superscript

Privacy Policy

Everlasting Legacies LLC

Effective Date: [INSERT EFFECTIVE DATE] Last Revised: September 13, 2026

Your privacy is important to us. This Privacy Policy explains how Everlasting Legacies LLC collects, uses, shares, and protects your personal information in connection with our insurance products and services. Please read this policy carefully.

SECTION 1: INTRODUCTION AND SCOPE

1.1 About This Policy. This Privacy Policy ("Policy") describes the privacy practices of Everlasting Legacies LLC, a limited liability company organized under the laws of the State of [INSERT STATE] ("Company," "we," "us," or "our"). This Policy applies to all personal information we collect from or about individuals ("you" or "your") who apply for, purchase, or maintain insurance products or services offered by Everlasting Legacies LLC, including life insurance, property and casualty insurance, health insurance, and general liability insurance.

1.2 Scope of Application. This Policy applies to information collected:

  • Through our website(s) and mobile applications;

  • Through insurance applications, enrollment forms, and WorkForms;

  • In connection with the underwriting, issuance, and administration of insurance policies;

  • Through claims processing and customer service interactions;

  • Via telephone, email, text message (SMS), and other electronic communications;

  • From third-party sources such as consumer reporting agencies, medical information bureaus, lead vendors, and public records.

1.3 Relationship to Other Notices. This Policy supplements, and should be read together with, any specific notices provided to you at the time of data collection, including our HIPAA Notice of Privacy Practices (Section 10) and our Gramm-Leach-Bliley Act Annual Privacy Notice (Section 11). In the event of a conflict between this Policy and a more specific notice, the more specific notice shall control.

1.4 Acceptance. By applying for, enrolling in, or maintaining any insurance product or service with Everlasting Legacies LLC, or by using our website or mobile applications, you acknowledge that you have read and understood this Privacy Policy.

SECTION 2: INFORMATION WE COLLECT

We collect several categories of personal information in connection with our insurance products and services.

2.1 Personal Identification Information. We collect information that identifies you as an individual, including:

  • Full legal name, date of birth, and gender;

  • Government-issued identification numbers (e.g., Social Security number, driver's license number);

  • Postal address, email address, and telephone number(s);

  • Marital status, family composition, and beneficiary information;

  • Signature (electronic or physical).

2.2 Financial Information. In connection with underwriting, premium billing, and claims, we collect:

  • Bank account and routing numbers;

  • Credit and debit card information;

  • Credit history and credit scores;

  • Income, assets, and financial account information;

  • Claims payment history and loss history reports.

2.3 Health and Medical Information. For health insurance and life insurance underwriting and claims, we may collect:

  • Medical history, diagnoses, and treatment records;

  • Prescription drug history;

  • Mental health and substance use disorder information;

  • Disability status;

  • Information from medical examinations conducted in connection with underwriting;

  • Information from the Medical Information Bureau (MIB).

Health information is subject to additional protections under HIPAA and applicable state law. See Section 10 for details.

2.4 Property Information. For property and casualty insurance, we may collect:

  • Property address, description, and ownership information;

  • Vehicle identification numbers (VINs), make, model, and year;

  • Driving records and motor vehicle reports;

  • Prior loss and claims history;

  • Property inspection reports and photographs.

2.5 Usage and Technical Data. When you use our website or mobile applications, we automatically collect:

  • IP address, browser type, and operating system;

  • Pages visited, links clicked, and time spent on pages;

  • Device identifiers and mobile advertising IDs;

  • Geolocation data (with your consent where required);

  • Cookies and similar tracking technologies (see Section 6).

2.6 Communications Data. We collect records of your communications with us, including:

  • Telephone call recordings (where permitted by law);

  • Email and text message (SMS) correspondence;

  • Chat and customer service interaction logs;

  • Records of your consent to receive communications.

2.7 Information from Third Parties. We may receive information about you from third parties, including:

  • Consumer reporting agencies and credit bureaus;

  • The Medical Information Bureau (MIB);

  • State motor vehicle departments;

  • Prior insurers and claims databases (e.g., CLUE reports);

  • Publicly available records;

  • Your employer or group plan sponsor (for group insurance);

  • Agents, brokers, and other insurance intermediaries.

2.8 Information from Third-Party Lead Vendors. Everlasting Legacies LLC receives personal information from third-party lead vendors who collect consumer data on our behalf or on behalf of the insurance marketplace. This information may include:

  • Full name and contact details (mailing address, email address, telephone and mobile number);

  • Insurance interest and product preference data (e.g., type of coverage sought, coverage amount requested);

  • Demographic information relevant to insurance underwriting;

  • Records of consent to be contacted by insurance providers, including Everlasting Legacies LLC.

Lead vendors who provide data to Everlasting Legacies LLC are contractually required to collect such information in compliance with all applicable federal and state privacy and consumer protection laws, including the TCPA, GLBA, and applicable state insurance privacy laws. Everlasting Legacies LLC uses lead vendor data solely for the purpose of contacting consumers regarding insurance products and services for which they have expressed interest and, where applicable, for which they have provided consent to be contacted.

If you believe your information was provided to us by a lead vendor and you did not authorize such sharing, or if you wish to opt out of further contact, please see Section 8 (Your Privacy Rights) or contact us using the information in Section 15.

SECTION 3: HOW WE USE YOUR INFORMATION

We use the personal information we collect for the following purposes:

3.1 Insurance Operations.

  • Evaluating and processing insurance applications;

  • Underwriting and risk assessment;

  • Issuing, administering, and renewing insurance policies;

  • Processing premium payments and billing;

  • Investigating, evaluating, and paying claims;

  • Detecting and preventing insurance fraud.

3.2 Customer Service and Communications.

  • Responding to your inquiries and requests;

  • Sending policy documents, billing statements, and renewal notices;

  • Providing claims status updates and notifications;

  • Sending service-related text messages and emails (see Section 5);

  • Conducting customer satisfaction surveys.

3.3 Legal and Regulatory Compliance.

  • Complying with applicable federal and state insurance laws and regulations;

  • Responding to legal process, court orders, and regulatory inquiries;

  • Maintaining records as required by law;

  • Exercising and defending legal rights.

3.4 Business Operations.

  • Analyzing and improving our products, services, and operations;

  • Conducting actuarial and statistical analysis;

  • Training employees and quality assurance;

  • Managing our business relationships with agents, brokers, and vendors.

3.5 Marketing. With your consent where required by law, we may use your information to:

  • Inform you about additional insurance products and services that may be of interest to you;

  • Send promotional communications by mail, email, or telephone.

You may opt out of marketing communications at any time as described in Section 8.

SECTION 4: HOW WE SHARE YOUR INFORMATION

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers. We share information with third-party service providers who perform services on our behalf, including:

  • Claims administrators and adjusters;

  • Payment processors and billing vendors;

  • Information technology and data hosting providers;

  • Printing and mailing services;

  • Fraud detection and analytics providers;

  • Customer service platforms.

Service providers are contractually required to use your information only to perform services for us and to maintain appropriate security safeguards.

4.2 Reinsurers. We may share information with reinsurance companies that assume a portion of the risk under our policies, as necessary for reinsurance purposes.

4.3 Insurance Industry Databases. We may report and access information through industry databases, including the Medical Information Bureau (MIB), CLUE (Comprehensive Loss Underwriting Exchange), and similar databases, as permitted by law and disclosed in our underwriting notices.

4.4 Agents and Brokers. We may share information with licensed insurance agents and brokers who assist in the placement and servicing of your policy.

4.5 Third-Party Lead Vendors. Everlasting Legacies LLC receives consumer data from third-party lead vendors as part of our insurance marketing and outreach operations. These lead vendors collect consumer information — including name, contact details, and insurance interest data — and provide it to Everlasting Legacies LLC for the purpose of facilitating contact with consumers who have expressed interest in insurance products.

All third-party lead vendors engaged by Everlasting Legacies LLC are contractually required to:

  • Collect and handle consumer data in compliance with all applicable federal and state privacy laws, including the TCPA, GLBA, CCPA/CPRA, and applicable state insurance privacy regulations;

  • Obtain all legally required consents from consumers prior to transferring data to Everlasting Legacies LLC, including prior express written consent for SMS/text messaging where applicable;

  • Maintain records of consumer consent and make such records available to Everlasting Legacies LLC upon request;

  • Refrain from selling or sharing consumer data with unauthorized third parties;

  • Promptly notify Everlasting Legacies LLC of any data breach or unauthorized disclosure involving consumer data provided to us.

Everlasting Legacies LLC conducts due diligence on its lead vendor partners and reserves the right to terminate relationships with vendors who fail to comply with applicable legal requirements or our contractual standards.

4.6 Legal and Regulatory Disclosures. We may disclose information as required or permitted by law, including:

  • In response to a subpoena, court order, or legal process;

  • To comply with applicable laws and regulations;

  • To report suspected fraud or criminal activity to law enforcement;

  • To state insurance departments and other regulatory authorities.

4.7 Business Transfers. In the event of a merger, acquisition, sale of assets, or other business transaction, your information may be transferred to the successor entity, subject to the same privacy protections described in this Policy.

4.8 With Your Consent. We may share your information with third parties for other purposes with your prior written consent.

4.9 No Sale of Personal Information. Everlasting Legacies LLC does not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes.

SECTION 5: SMS / TEXT MESSAGING OPT-IN

This section governs all text message (SMS/MMS) communications sent by Everlasting Legacies LLC. Please read it carefully.

5.1 Opt-In Consent. Everlasting Legacies LLC will only send you text messages (SMS/MMS) if you have provided your prior express written consent to receive such messages. You may provide consent in any of the following ways:

  • Online Enrollment: By checking the SMS opt-in checkbox on our online application, account portal, or WorkForm and submitting your mobile telephone number;

  • Paper Application: By signing and submitting a paper application or enrollment form that includes SMS opt-in language;

  • Text-to-Join: By texting the keyword [INSERT KEYWORD] to [INSERT SHORT CODE OR LONG CODE NUMBER];

  • Verbal Consent: By providing verbal consent during a recorded customer service call, where permitted by applicable law;

  • Via Lead Vendor: By providing prior express written consent through a third-party lead vendor's website, form, or platform that explicitly names Everlasting Legacies LLC as an authorized sender (see Section 5.11 — Third-Party Consent Collection).

By opting in, you expressly consent to receive recurring automated and non-automated text messages from Everlasting Legacies LLC at the mobile telephone number you provide. Your consent is not a condition of purchasing any insurance product or service.

5.2 Types of Text Messages Sent. Once you have opted in, Everlasting Legacies LLC may send you text messages for the following purposes:

  • Policy Updates: Notifications regarding changes to your policy terms, coverage, or status;

  • Billing and Premium Reminders: Reminders about upcoming premium due dates, payment confirmations, and notices of returned payments;

  • Claims Status Updates: Notifications regarding the status of a submitted claim, requests for additional information, and claim resolution notices;

  • Renewal Notices: Alerts regarding upcoming policy renewals and renewal terms;

  • Account Alerts: Security alerts, login verification codes (two-factor authentication), and account activity notifications;

  • Appointment Reminders: Reminders for scheduled inspections, medical examinations, or agent appointments;

  • Emergency and Urgent Alerts: Time-sensitive communications regarding coverage gaps, cancellation warnings, or other urgent matters;

  • Customer Service Follow-Up: Follow-up messages related to open customer service inquiries or claims;

  • Insurance Outreach: Initial outreach to consumers who have expressed interest in Everlasting Legacies LLC insurance products and provided consent through a lead vendor platform.

5.3 Message Frequency. Message frequency varies based on your policy type, account activity, and the nature of your insurance relationship with us. You may receive up to [INSERT NUMBER] text messages per month per enrolled mobile number. During periods of active claims or billing activity, message frequency may be higher.

5.4 Standard Message and Data Rates.

Message and data rates may apply. Text messages sent by Everlasting Legacies LLC are subject to the standard messaging and data rates charged by your mobile carrier. Everlasting Legacies LLC is not responsible for any charges imposed by your mobile carrier in connection with text messages you receive from us. Please contact your mobile carrier if you have questions about your messaging plan.

5.5 How to Opt Out. You may opt out of receiving text messages from Everlasting Legacies LLC at any time using any of the following methods:

  • Reply STOP: Reply STOP to any text message you receive from us. You will receive a one-time confirmation message acknowledging your opt-out, and no further marketing or service text messages will be sent to that number, except as required by law;

  • Reply CANCEL, END, QUIT, or UNSUBSCRIBE: These keywords are also recognized and will process your opt-out request;

  • Online Account Portal: Log in to your account at [INSERT WEBSITE URL] and update your communication preferences;

  • Customer Service: Contact our Customer Service team at [INSERT PHONE NUMBER] or [INSERT EMAIL ADDRESS] to request removal from our text messaging list.

Opt-out requests will be processed within ten (10) business days. Consumers who provided consent through a lead vendor and wish to revoke that consent may do so at any time using any of the opt-out methods listed above — revocation of consent is effective regardless of the channel through which consent was originally obtained.

Please note that opting out of marketing text messages will not affect your receipt of legally required notices or transactional messages directly related to your active policy, to the extent permitted by applicable law.

5.6 Help and Support. For help with our text messaging program, reply HELP to any text message you receive from us, or contact our Customer Service team at [INSERT PHONE NUMBER]. You may also visit [INSERT WEBSITE URL] for additional information.

5.7 No Sharing of Opt-In Data for Third-Party Marketing. Everlasting Legacies LLC will not share, sell, rent, or disclose your mobile telephone number or SMS opt-in consent data to any third party for that third party's own marketing or promotional purposes. Your opt-in information may be shared with our service providers solely for the purpose of facilitating the delivery of text messages on our behalf, subject to confidentiality obligations. This commitment applies regardless of any other data sharing described in Section 4 of this Policy.

5.8 TCPA Compliance. Everlasting Legacies LLC's text messaging program is designed and operated in compliance with the Telephone Consumer Protection Act (TCPA), 47 U.S.C. § 227, and the regulations promulgated thereunder by the Federal Communications Commission (FCC), as well as applicable state telemarketing and communications laws. Specifically:

  • We obtain prior express written consent before sending any marketing or promotional text messages, whether collected directly or through a lead vendor;

  • Consent obtained through lead vendors is held to the same legal standard as directly collected consent — it must be prior, express, written, and clearly and conspicuously disclosed;

  • We honor opt-out requests promptly and maintain a do-not-text list;

  • We do not send text messages to numbers on the National Do Not Call Registry for marketing purposes;

  • We identify ourselves in each text message communication;

  • We do not use deceptive or misleading practices in connection with our text messaging program;

  • We maintain records of all opt-in consents and opt-out requests as required by law, including records of consents obtained through lead vendors.

If you believe you have received a text message from us in error or in violation of the TCPA, please contact us immediately at [INSERT CONTACT INFORMATION].

5.9 Supported Carriers. Our text messaging program is supported by major U.S. wireless carriers, including but not limited to AT&T, Verizon, T-Mobile, Sprint, and U.S. Cellular. Carrier support is subject to change. Everlasting Legacies LLC is not liable for delayed or undelivered messages due to carrier issues.

5.10 Mobile Number Changes. If you change your mobile telephone number, you are responsible for notifying us promptly to update your contact information and ensure that text messages are not sent to a number you no longer control. You may update your mobile number through your online account portal or by contacting Customer Service.

5.11 Third-Party Consent Collection. Everlasting Legacies LLC partners with third-party lead vendors who present SMS opt-in disclosures on our behalf as part of their consumer-facing websites, forms, and platforms. The following standards govern all third-party consent collection:

  • Explicit Naming Requirement: Any opt-in disclosure presented by a lead vendor on behalf of Everlasting Legacies LLC must explicitly and conspicuously identify Everlasting Legacies LLC by name as a company authorized to send text messages to the consumer. Generic disclosures that do not name Everlasting Legacies LLC specifically do not constitute valid consent for our text messaging program.

  • Prior Express Written Consent Standard: Consent collected by lead vendors on our behalf must meet the TCPA standard of prior express written consent — meaning the consumer must take an affirmative action (e.g., checking an unchecked opt-in box, signing a form) to provide consent, and the disclosure must clearly describe the nature of the communications to be received.

  • Treatment as Direct Consent: Consent validly obtained by a lead vendor on behalf of Everlasting Legacies LLC, in accordance with the standards described in this Section, is treated by Everlasting Legacies LLC as equivalent to consent provided directly to us. We rely on such consent as the legal basis for initiating text message communications with the consumer.

  • Everlasting Legacies LLC's Responsibility: Everlasting Legacies LLC takes responsibility for ensuring that opt-in disclosures presented by our lead vendor partners meet applicable TCPA and FCC standards. We conduct due diligence on our lead vendor partners, require contractual representations regarding consent quality, and audit consent records on a periodic basis.

  • Consumer Rights Unaffected: A consumer's right to opt out of text messages from Everlasting Legacies LLC is not affected by the channel through which consent was originally obtained. Consumers who provided consent through a lead vendor platform retain the full right to revoke consent at any time by replying STOP or using any other opt-out method described in Section 5.5.

  • No Assumed Consent: Everlasting Legacies LLC does not assume or infer SMS consent from the mere transfer of a consumer's contact information by a lead vendor. Consent must be affirmatively and explicitly granted by the consumer and documented by the lead vendor before Everlasting Legacies LLC will initiate text message communications.

SECTION 6: COOKIES AND TRACKING TECHNOLOGIES

6.1 Use of Cookies. Our website and mobile applications use cookies and similar tracking technologies to enhance your experience, analyze usage, and support our business operations. A "cookie" is a small text file placed on your device by a website you visit.

6.2 Types of Cookies We Use.

Cookie Type

Purpose

Essential Cookies

Required for the website to function; cannot be disabled

Performance Cookies

Collect anonymous data on how visitors use our site

Functional Cookies

Remember your preferences and settings

Analytics Cookies

Help us understand traffic patterns and improve our services

Marketing Cookies

Used to deliver relevant advertisements (with consent)

 

6.3 Third-Party Tracking. We may permit third-party analytics providers (e.g., Google Analytics) and advertising partners to place cookies or tracking pixels on our website. These third parties may collect information about your online activities over time and across different websites.

6.4 Your Cookie Choices. You may control cookies through your browser settings or our cookie preference center at [INSERT WEBSITE URL]. Please note that disabling certain cookies may affect the functionality of our website. Most browsers allow you to refuse cookies or delete existing cookies.

6.5 Do Not Track. Some browsers transmit "Do Not Track" signals. Our website currently does not respond to Do Not Track signals. We will update this Policy if our practices change.

SECTION 7: DATA RETENTION

7.1 Retention Periods. We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to:

  • Maintain your insurance policy and administer claims;

  • Comply with applicable legal, regulatory, and contractual obligations;

  • Resolve disputes and enforce our agreements;

  • Conduct actuarial and statistical analysis.

7.2 Retention Standards. As a general guideline, we retain:

  • Policy and underwriting records: For the duration of the policy plus a minimum of seven (7) years after policy expiration or termination, or longer as required by applicable state law;

  • Claims records: For a minimum of seven (7) years after final claim resolution, or longer as required by applicable law;

  • Health information: In accordance with HIPAA and applicable state health records retention laws;

  • Financial records: For a minimum of seven (7) years as required by applicable tax and financial regulations;

  • Marketing and consent records (including lead vendor consent records): For the duration of the relationship plus a minimum of five (5) years, or as required by applicable law. TCPA consent records are retained for a minimum of four (4) years from the date of consent or last contact, whichever is later.

7.3 Secure Disposal. When personal information is no longer needed, we dispose of it securely using methods appropriate to the sensitivity of the information, including shredding of physical records and secure deletion of electronic records.

SECTION 8: YOUR PRIVACY RIGHTS

8.1 General Rights. Depending on your state of residence and applicable law, you may have the following rights with respect to your personal information:

  • Right to Know / Access: The right to request information about the categories and specific pieces of personal information we have collected about you, including information received from lead vendors;

  • Right to Correction: The right to request correction of inaccurate personal information;

  • Right to Deletion: The right to request deletion of your personal information, subject to certain exceptions;

  • Right to Opt Out of Sale: The right to opt out of the sale of your personal information (note: we do not sell personal information);

  • Right to Non-Discrimination: The right not to be discriminated against for exercising your privacy rights.

8.2 California Residents — CCPA/CPRA Rights. If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including:

  • The right to know what personal information is collected, used, shared, or sold;

  • The right to delete personal information we hold about you;

  • The right to correct inaccurate personal information;

  • The right to opt out of the sale or sharing of personal information;

  • The right to limit the use and disclosure of sensitive personal information;

  • The right to non-discrimination for exercising CCPA rights.

To submit a CCPA request, please contact us using the information in Section 15 or visit [INSERT WEBSITE URL/CCPA REQUEST PORTAL]. We will respond to verifiable consumer requests within forty-five (45) days, with a possible extension of an additional forty-five (45) days where reasonably necessary.

8.3 Other State Privacy Rights. Residents of other states, including but not limited to Virginia, Colorado, Connecticut, Texas, and other states with comprehensive privacy laws, may have similar rights under applicable state law. We will honor privacy rights requests as required by the law of your state of residence.

8.4 Insurance-Specific Rights. Under applicable state insurance privacy laws (based on the NAIC Insurance Information and Privacy Protection Model Act), you may have the right to:

  • Access personal information we have collected about you in connection with an insurance transaction;

  • Correct, amend, or delete inaccurate personal information;

  • Receive notice of our information practices.

8.5 How to Exercise Your Rights. To exercise any of the rights described in this Section, please:

  • Submit a written request to [INSERT EMAIL ADDRESS];

  • Call our Privacy Hotline at [INSERT PHONE NUMBER];

  • Submit a request through our online privacy request portal at [INSERT WEBSITE URL].

We may need to verify your identity before processing your request. We will not charge a fee for processing your request unless it is excessive or repetitive.

8.6 Opt Out of Marketing. You may opt out of receiving marketing communications from us at any time by:

  • Clicking the "unsubscribe" link in any marketing email;

  • Replying STOP to any marketing text message;

  • Contacting Customer Service at [INSERT PHONE NUMBER].

Please note that opting out of marketing communications will not affect your receipt of transactional or legally required communications.

SECTION 9: CHILDREN'S PRIVACY

9.1 Age Restriction. Our insurance products and services, website, and mobile applications are not directed to children under the age of thirteen (13), and we do not knowingly collect personal information from children under thirteen (13) without verifiable parental consent.

9.2 Minors as Insureds. Where a minor is named as an insured under a policy (e.g., a child life insurance rider or dependent health coverage), personal information about the minor is collected and used solely for the purpose of administering the applicable coverage and is subject to the same protections described in this Policy.

9.3 COPPA Compliance. We comply with the Children's Online Privacy Protection Act (COPPA). If we become aware that we have inadvertently collected personal information from a child under thirteen (13) without appropriate consent, we will take steps to delete such information promptly. If you believe we have collected information from a child under thirteen (13), please contact us at [INSERT EMAIL ADDRESS].

SECTION 10: HIPAA NOTICE OF PRIVACY PRACTICES

10.1 Applicability. This Section applies to protected health information ("PHI") collected and maintained by Everlasting Legacies LLC in connection with health insurance products and services. Everlasting Legacies LLC is a covered entity or business associate (as applicable) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH).

10.2 What is Protected Health Information. PHI is individually identifiable health information that relates to your past, present, or future physical or mental health condition, the provision of health care to you, or the past, present, or future payment for health care. PHI includes information in any form — oral, written, or electronic.

10.3 How We Use and Disclose PHI. We may use and disclose your PHI without your authorization for the following purposes:

  • Treatment: To facilitate the provision of health care services by your providers;

  • Payment: To process claims, determine coverage, and coordinate benefits;

  • Health Care Operations: For quality assessment, underwriting, auditing, and other operational purposes;

  • As Required by Law: To comply with legal obligations, including reporting to public health authorities;

  • Business Associates: To service providers ("business associates") who perform functions on our behalf under written agreements that require them to protect your PHI.

10.4 Uses and Disclosures Requiring Authorization. We will obtain your written authorization before using or disclosing your PHI for purposes other than those described above, including:

  • Most uses and disclosures of psychotherapy notes;

  • Uses and disclosures of PHI for marketing purposes;

  • Sale of PHI.

10.5 Your HIPAA Rights. With respect to your PHI, you have the right to:

  • Access: Request a copy of your PHI in our records;

  • Amendment: Request amendment of PHI you believe is inaccurate or incomplete;

  • Accounting of Disclosures: Request a list of certain disclosures we have made of your PHI;

  • Restrictions: Request restrictions on certain uses and disclosures of your PHI;

  • Confidential Communications: Request that we communicate with you about your PHI in a specific way or at a specific location;

  • Breach Notification: Receive notification in the event of a breach of your unsecured PHI.

10.6 Full HIPAA Notice. Our full HIPAA Notice of Privacy Practices is available at [INSERT WEBSITE URL] and will be provided to you upon enrollment in a health insurance plan and upon request. The full Notice contains additional details about our privacy practices and your rights.

10.7 Complaints. If you believe your HIPAA privacy rights have been violated, you may file a complaint with us at [INSERT EMAIL ADDRESS] or with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr. We will not retaliate against you for filing a complaint.

SECTION 11: GRAMM-LEACH-BLILEY ACT (GLBA) NOTICE

11.1 Applicability. This Section constitutes the annual privacy notice required by the Gramm-Leach-Bliley Act (GLBA), 15 U.S.C. §§ 6801–6809, and the regulations promulgated thereunder by the Federal Trade Commission and applicable state insurance regulators.

11.2 Information We Collect. We collect nonpublic personal information ("NPI") about you from the following sources:

  • Information you provide on applications and other forms;

  • Information about your transactions with us, our affiliates, or others;

  • Information we receive from consumer reporting agencies and other third parties;

  • Information received from third-party lead vendors who collect data on our behalf.

11.3 Information We Disclose. We may disclose NPI about you to the following types of third parties:

  • Financial service providers (e.g., payment processors);

  • Non-financial companies that perform services on our behalf (e.g., claims administrators, IT vendors);

  • Other companies as permitted or required by law.

11.4 Opt-Out Rights. To the extent we share NPI with non-affiliated third parties in ways not described in this Policy, you have the right to opt out of such sharing. To opt out, please contact us at [INSERT PHONE NUMBER] or [INSERT EMAIL ADDRESS]. If you do not opt out, we may share your NPI as described in this Policy.

11.5 Confidentiality and Security. We restrict access to NPI about you to those employees and service providers who need to know that information to provide products or services to you. We maintain physical, electronic, and procedural safeguards that comply with federal and state regulations to guard your NPI.

11.6 Former Customers. We continue to protect the NPI of former customers in accordance with this Policy and applicable law.

SECTION 12: DATA SECURITY

12.1 Security Program. Everlasting Legacies LLC maintains a comprehensive written information security program designed to protect the confidentiality, integrity, and availability of personal information in our custody or control. Our security program includes administrative, technical, and physical safeguards appropriate to the size, complexity, and sensitivity of the information we maintain.

12.2 Technical Safeguards. Our technical security measures include:

  • Encryption of personal information in transit (TLS/SSL) and at rest;

  • Multi-factor authentication for access to systems containing personal information;

  • Firewalls, intrusion detection systems, and vulnerability management;

  • Regular security assessments and penetration testing;

  • Access controls limiting employee access to personal information on a need-to-know basis.

12.3 Employee Training. All employees with access to personal information receive regular privacy and security training. Employees are subject to confidentiality obligations and disciplinary action for unauthorized use or disclosure of personal information.

12.4 Vendor Management. We require all third-party service providers and lead vendors with access to personal information to maintain appropriate security safeguards and to use personal information only as authorized by us.

12.5 Breach Notification. In the event of a security breach involving your personal information, we will notify you as required by applicable federal and state breach notification laws, including applicable state insurance data security laws. Notification will be provided in the most expedient time possible and without unreasonable delay.

12.6 Limitations. While we take reasonable steps to protect your personal information, no security system is impenetrable. We cannot guarantee the absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials and for notifying us promptly if you suspect unauthorized access to your account.

SECTION 13: THIRD-PARTY LINKS

13.1 External Websites. Our website and communications may contain links to third-party websites, applications, or services that are not owned or controlled by Everlasting Legacies LLC. This Privacy Policy does not apply to third-party websites or services.

13.2 No Endorsement. The inclusion of a link to a third-party website does not constitute an endorsement, recommendation, or approval of that website or its privacy practices. We encourage you to review the privacy policies of any third-party websites you visit.

13.3 No Responsibility. Everlasting Legacies LLC is not responsible for the privacy practices, content, or security of third-party websites or services. Your interactions with third-party websites are governed by their respective privacy policies and terms of use.

SECTION 14: CHANGES TO THIS POLICY

14.1 Right to Update. Everlasting Legacies LLC reserves the right to update or modify this Privacy Policy at any time to reflect changes in our practices, applicable law, or business operations. We will post the revised Policy on our website with an updated "Last Revised" date.

14.2 Notice of Material Changes. For material changes to this Policy, we will provide advance notice by:

  • Posting a prominent notice on our website;

  • Sending an email notification to the email address on file for your account; and/or

  • Including a notice with your next billing statement or policy renewal.

For health insurance Policyholders, material changes to our HIPAA Notice of Privacy Practices will be communicated in accordance with HIPAA requirements.

14.3 Continued Use as Acceptance. Your continued use of our products, services, or website following the effective date of any updated Policy constitutes your acceptance of the revised Policy. If you do not agree to the revised Policy, you should discontinue use of our services and contact us to discuss your options.

14.4 Prior Versions. Prior versions of this Privacy Policy are available upon request by contacting us at [INSERT EMAIL ADDRESS].

SECTION 15: CONTACT INFORMATION

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Everlasting Legacies LLC — Privacy Office

Contact Type

Details

Mailing Address

Attn: Privacy Officer, [INSERT STREET ADDRESS], [INSERT CITY, STATE, ZIP CODE]

Privacy Hotline

[INSERT PHONE NUMBER]

Privacy Email

[INSERT PRIVACY EMAIL ADDRESS]

Website / Privacy Portal

[INSERT WEBSITE URL]

HIPAA Complaints

[INSERT HIPAA COMPLAINT EMAIL/ADDRESS]

TCPA / SMS Inquiries

[INSERT SMS CONTACT EMAIL OR PHONE]

Lead Vendor Data Inquiries

[INSERT LEAD VENDOR DATA CONTACT EMAIL OR PHONE]

Hours of Operation

[INSERT BUSINESS HOURS]

 

For complaints to state insurance regulators, please visit the National Association of Insurance Commissioners (NAIC) at www.naic.org for your state's insurance department contact information.

For HIPAA complaints to the federal government, contact the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr or call 1-800-368-1019.

For TCPA complaints or inquiries, you may also contact the Federal Communications Commission (FCC) at www.fcc.gov/consumers/guides/filing-informal-complaint.

ACKNOWLEDGMENT

By using our services, website, or mobile applications, or by enrolling in any insurance product offered by Everlasting Legacies LLC, you acknowledge that:

  1. You have read and understood this Privacy Policy in its entirety;

  2. You consent to the collection, use, and disclosure of your personal information as described in this Policy;

  3. You understand your rights and how to exercise them;

  4. You understand that this Policy does not constitute legal advice and that you may consult an attorney for advice specific to your situation.

This Privacy Policy was prepared for Everlasting Legacies LLC. This document is intended as a general framework and does not constitute legal advice. Everlasting Legacies LLC should consult with licensed legal counsel to ensure compliance with all applicable federal and state privacy, insurance, and telecommunications laws and regulations — including HIPAA, GLBA, TCPA, CCPA/CPRA, and applicable state insurance privacy laws — before using this document.

© 2026 Everlasting Legacies LLC. All rights reserved.